Lead GRC Security Analyst
About the Role
We are seeking an experienced Lead GRC Automation Analyst to join an Information Security organization within a highly regulated financial services environment.
This is a hands-on role for someone who understands Governance, Risk, and Compliance but also knows how to build and automate processes. The ideal candidate will be comfortable identifying manual or inefficient GRC processes, designing better workflows, and personally helping implement automation that improves efficiency, accuracy, and audit readiness.
This person will also support security governance, control testing, audit activities, evidence collection, and compliance initiatives. The role offers an opportunity to help build and mature GRC capabilities while making a measurable impact through automation.
What You’ll Do
- Lead the design and implementation of GRC automation initiatives.
- Identify manual, repetitive, or inefficient compliance processes and develop solutions to streamline or automate them.
- Automate evidence/artifact gathering, control testing, reporting, and other repeatable GRC processes.
- Look across the GRC function for opportunities to improve processes, eliminate manual work, and create scalable solutions.
- Support internal audits and regulatory examinations through evidence collection, documentation, and stakeholder coordination.
- Perform control validation and testing and document results.
- Identify control deficiencies, track remediation, and partner with stakeholders to resolve findings.
- Develop and maintain clear process narratives, control documentation, and supporting evidence.
- Work with GRC platforms and related technology to improve workflows and reporting.
- Develop metrics and reporting related to control effectiveness, risk, compliance, and remediation.
- Support policy and standards governance, including reviews and updates.
- Partner with technical and business stakeholders to understand requirements and implement practical solutions.
- Communicate findings, recommendations, and project progress to both technical teams and leadership.
Requirements
What We’re Looking For
- 5–8+ years of experience in Information Security GRC, IT Audit, Risk, Controls, Compliance, or a related field.
- Hands-on experience designing and implementing automation.
- Demonstrated ability to take a manual GRC or compliance process and build or implement a more automated and efficient solution.
- Strong understanding of IT General Controls (ITGCs), control testing, evidence collection, and remediation.
- Experience working with a GRC platform, preferably ServiceNow IRM or LogicGate.
- Experience working in a regulated environment, with financial services or banking experience strongly preferred.
- Understanding of common security and risk frameworks such as NIST, COBIT, ISO 27001, or similar.
- Strong analytical and problem-solving skills with exceptional attention to detail.
- Excellent written and verbal communication skills.
- Ability to work effectively with both technical and non-technical stakeholders.
- Comfortable working independently, taking ownership, and driving projects from concept through implementation.
You'll be redirected to Robert Half's application page
Job Details
Salary
$104K–$135K
Location
United States - Middleton WI
Job type
Temporary
Category
ServiceNow Development
Experience
5–8+ years
Posted
5 days ago
Job Highlights
- $104K–$135K salary
- 5–8+ years level role
- 100% Remote — open to candidates in United States
About Robert Half
This job is hosted by Robert Half. Clicking Apply opens their site.
Remote Work Style
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.